PULSE NAME
Covert Channels and Poor Decisions: The Tale of DNSMessenger
WHITE AlienVault 2017-03-02 Modified: 2017-03-02
114
IOCs
HIGH VOLUME
(Cisco) What initially drew our interest to this particular malware sample was a tweet published by security researcher on Twitter (thanks simpo!) regarding a Powershell script that he was analyzing that contained the base64 encoded string 'SourceFireSux'. Interestingly enough, Sourcefire was the only security vendor directly referenced in the Powershell script. We searched for the base64 encoded value which was referenced in the tweet, and were able to identify a sample that had been uploaded to the public malware analysis sandbox, Hybrid Analysis. Additionally, when we searched for the decoded string value we found a single search engine result that pointed to a Pastebin page. The hash listed in the Pastebin led us to a malicious Word document that had also been uploaded to a public sandbox. The Word document initiated the same multiple-stage infection process as the file from the Hybrid Analysis report we previously discovered and allowed us to reconstruct a more complete infection process.
Indicators of Compromise (114)
All FileHash-SHA256 domain
TYPEINDICATORDESCRIPTIONCREATED
FileHash-SHA256 6bf9d311ed16e059f9538b4c24c836cf421cf5c0c1f756fdfdeb9e1792ada8ba 2017-03-02
FileHash-SHA256 f9e54609f1f4136da71dbab8f57c2e68e84bcdc32a58cc12ad5f86334ac0eacf 2017-03-02
FileHash-SHA256 7f0a314f15a6f20ca6dced545fbc9ef8c1634f9ff8eb736deab73e46ae131458 2017-03-02
FileHash-SHA256 9b955d9d7f62d405da9cf05425c9b6dd3738ce09160c8a75d396a6de229d9dd7 2017-03-02
FileHash-SHA256 fd6e7fc11a325c498d73cf683ecbe90ddbf0e1ae1d540b811012bd6980eed882 2017-03-02
FileHash-SHA256 be5f4bfa35fc1b350d38d8ddc8e88d2dd357b84f254318b1f3b07160c3900750 2017-03-02
FileHash-SHA256 f82baa39ba44d9b356eb5d904917ad36446083f29dced8c5b34454955da89174 2017-03-02
FileHash-SHA256 340795d1f2c2bdab1f2382188a7b5c838e0a79d3f059d2db9eb274b0205f6981 2017-03-02
domain cnmah.pw 2017-03-02
domain ppdx.pw 2017-03-02
domain xhqd.pw 2017-03-02
domain vjro.club 2017-03-02
domain mjut.pw 2017-03-02
domain bwuk.club 2017-03-02
domain ooep.pw 2017-03-02
domain grij.us 2017-03-02
domain ldzp.pw 2017-03-02
domain zugh.us 2017-03-02
domain pafk.us 2017-03-02
domain futh.pw 2017-03-02
domain odwf.pw 2017-03-02
domain rzzc.pw 2017-03-02
domain pvze.club 2017-03-02
domain pbbk.us 2017-03-02
domain oaax.site 2017-03-02
domain oyaw.club 2017-03-02
domain coec.club 2017-03-02
domain utca.site 2017-03-02
domain soru.pw 2017-03-02
domain vxqt.us 2017-03-02
domain vwcq.us 2017-03-02
domain ufyb.club 2017-03-02
domain bvyv.club 2017-03-02
domain otzd.pw 2017-03-02
domain vpua.pw 2017-03-02
domain palj.us 2017-03-02
domain cihr.site 2017-03-02
domain jxhv.site 2017-03-02
domain reld.info 2017-03-02
domain mewt.us 2017-03-02
domain zody.pw 2017-03-02
domain nwrr.pw 2017-03-02
domain tsrs.pw 2017-03-02
domain vdfe.site 2017-03-02
domain oknz.club 2017-03-02
domain wvzu.pw 2017-03-02
domain dtxf.pw 2017-03-02
domain mfka.pw 2017-03-02
domain bpee.pw 2017-03-02
domain vqba.info 2017-03-02
domain nroq.pw 2017-03-02
domain lvrm.pw 2017-03-02
domain kshv.site 2017-03-02
domain gnoa.pw 2017-03-02
domain eter.pw 2017-03-02
domain ckwl.pw 2017-03-02
domain dyiud.com 2017-03-02
domain hvzr.info 2017-03-02
domain idjb.us 2017-03-02
domain ueox.club 2017-03-02
domain oxrp.info 2017-03-02
domain zjav.us 2017-03-02
domain mvze.pw 2017-03-02
domain turp.pw 2017-03-02
domain gjuc.pw 2017-03-02
domain mxfg.pw 2017-03-02
domain vxwy.pw 2017-03-02
domain mjet.pw 2017-03-02
domain aloqd.pw 2017-03-02
domain ysxy.pw 2017-03-02
domain lnoy.site 2017-03-02
domain jimw.club 2017-03-02
domain eady.club 2017-03-02
domain wqiy.info 2017-03-02
domain gxhp.top 2017-03-02
domain cuuo.us 2017-03-02
domain okiq.pw 2017-03-02
domain zdqp.pw 2017-03-02
domain qefg.info 2017-03-02
domain yedq.pw 2017-03-02
domain qznm.pw 2017-03-02
domain lvxf.pw 2017-03-02
domain gjcu.pw 2017-03-02
domain doof.pw 2017-03-02
domain dlex.pw 2017-03-02
domain algew.me 2017-03-02
domain lhlv.club 2017-03-02
domain zmyo.club 2017-03-02
domain dvso.pw 2017-03-02
domain swio.pw 2017-03-02
domain vkpo.us 2017-03-02
domain yamd.pw 2017-03-02
domain yqox.pw 2017-03-02
domain jomp.site 2017-03-02
domain kwoe.us 2017-03-02
domain rnkj.pw 2017-03-02
domain cspg.pw 2017-03-02
domain zjvz.pw 2017-03-02
domain ooyh.us 2017-03-02
domain fhyi.club 2017-03-02
domain daskd.me 2017-03-02
domain qlpa.club 2017-03-02
domain fbjz.pw 2017-03-02
domain nxpu.site 2017-03-02
domain sgvt.pw 2017-03-02
domain enuv.club 2017-03-02
domain cgqy.us 2017-03-02
domain kjke.pw 2017-03-02
domain ihrs.pw 2017-03-02
domain odyr.us 2017-03-02
domain wfsv.us 2017-03-02
domain dbxa.pw 2017-03-02
domain tijm.pw 2017-03-02
domain zcnt.pw 2017-03-02